Vulnerability Description
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Solaris | 2.6 |
| Sun | Sunos | <= 5.9 |
References
- http://www.securityfocus.com/archive/1/177200
- http://www.securityfocus.com/bid/2601ExploitVendor Advisory
- http://www.securityfocus.com/archive/1/177200
- http://www.securityfocus.com/bid/2601ExploitVendor Advisory
FAQ
What is CVE-2001-0421?
CVE-2001-0421 is a vulnerability with a CVSS score of 6.4 (MEDIUM). FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invali...
How severe is CVE-2001-0421?
CVE-2001-0421 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0421?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Solaris, Sun Sunos.